MCP agents
Domestic Monero exposes a hosted remote MCP server so an AI client can call the same offer, trade, and profile actions you already have in the Mini App — through tools instead of taps. The powers match your session. The UI is different.
This page explains what that is, when it helps, how trust works, and what it refuses to be. Install steps live in MCP agent setup. Tool names and recipes live in MCP tools.
What this is
Model Context Protocol (MCP) lets a host (Cursor, Claude, and similar) discover and call tools on a server. Domestic Monero runs a remote MCP endpoint over Streamable HTTP.
Endpoint: https://mcp.domesticmonero.com/mcp
The host root without /mcp is not the MCP path. Clients must paste the full URL.
Tools run as your Mini App user. They are not a separate venue, not a second account, and not a wallet daemon. If the Mini App would reject an action for your session, MCP rejects it the same way.
Use cases
Use MCP when you want an agent to drive product actions under supervision:
| Job | Tools (examples) |
|---|---|
| Browse and act on offers | offer_query, offer_create, offer_accept, offer_cancel |
| Follow a trade | trade_query, trade_get, trade_stake_info, trade_cancel |
| Payment and settlement steps | trade_payment_proof, trade_acknowledge_share, trade_resend_share, trade_withdraw |
| Profile and market context | profile_get, profile_update, profile_trading_limits, ticker_rates |
| Seller refund after cancel | trade_refund_preview → trade_refund (two-step) |
Identity check before anything else: auth_whoami.
Do not use MCP to invent wallet RPC, monerod control, or operator admin. Those tools are not on this server.
Mental model
AI client (Cursor / Claude / …)
→ Streamable HTTP
→ https://mcp.domesticmonero.com/mcp
→ Domestic Monero MCP tools
→ same user session rules as the Mini App
- You open the Mini App from the official bot and publish a
DM_TOKENon Profile → MCP access. - The client sends every MCP request with
Authorization: Bearer <DM_TOKEN>. - The server maps that Bearer to your user and exposes tools that proxy the same product actions.
- Trade settlement still needs the right chip, your trade share, and coordinated 2-of-3 rules — MCP does not bypass multisig. See 2-of-3 multisig.
Auth and trust
Auth is Bearer token, PAT-style — not an OAuth login dance on this host.
| Fact | Value |
|---|---|
| Token field | DM_TOKEN |
| Header | Authorization: Bearer <DM_TOKEN> |
| Prefix | dm_… |
| Visibility | Full value shown once on publish |
| Active tokens | At most one. Rotate = Revoke, then publish again |
| Without Bearer | HTTP 401 — Authorization Bearer required (DM_TOKEN) |
Treat DM_TOKEN like a session secret. Anyone with the token can call every exposed tool as you until you revoke it.
Some MCP hosts authenticate with OAuth (scopes, discovery, browser consent). Domestic Monero’s public MCP path uses a static Bearer you publish in Profile. Configure headers.Authorization (or the host’s Request headers field). Do not invent OAuth PRM, scopes, or client registration for this product — we do not ship that on the MCP endpoint.
Safety
- The agent can call any tool the server lists once connected. Prefer client tool allowlists / approval prompts when the host offers them.
- Creating or cancelling offers, submitting payment proof, withdrawing, and refunding are side-effecting. Confirm refs and amounts before you let the agent proceed.
- Trade share and multisig rules still apply for withdraw and refund. Losing the share still blocks settlement the same way as in the Mini App.
- Never paste
DM_TOKEN, trade share, seeds, or OpenPGP passphrases into unofficial chats. - Human help stays on the official bot
/supportwith Trade #ref when a trade is involved — Cancel Trade, Cancel Offer, and /support.
Non-goals
| Not this | Why |
|---|---|
| Wallet RPC / monerod | No wallet daemon tools |
| Ops / Operator console | No admin surface for users |
| Second trading venue | Same offers and trades as the Mini App |
| Escrow-admin custody | Settlement remains 2-of-3 / trade-share gated — not chat escrow |
| Instant-swap custody | Peer offers and timers, not Instant deposit addresses |
Official Mini App entry remains https://t.me/domestic_monero_bot/app only.
Offizieller Bot: @domestic_monero_bot — Mini App öffnen
Where to go next
- MCP agent setup — publish token, Cursor / Claude / curl
- MCP tools — full catalog, recipes, troubleshooting
- Your first trade — chips and stages the tools still obey
- 2-of-3 multisig — trade share and settlement words